環(huán)境配置
1.安裝docker-ce
curl -fsSL https://get.docker.com | bash -s docker --mirror Aliyun
2.安裝kubernetes
sudo apt update && sudo apt install -y apt-transport-https curl
curl -s https://mirrors.aliyun.com/kubernetes/apt/doc/apt-key.gpg | sudo apt-key add -
sudo vim /etc/apt/sources.list.d/kubernetes.list
deb https://mirrors.aliyun.com/kubernetes/apt/ kubernetes-xenial main
sudo apt update
sudo apt install -y kubelet kubeadm kubectl
sudo apt-mark hold kubelet kubeadm kubectl
systemctl restart kubelet && systemctl restart kubectl
3.禁用swap
sudo swapoff -a
sudo vi /etc/fstab 注釋swap
sudo reboot
4.初始化
sudo kubeadm init --image-repository registry.aliyuncs.com/google_containers --kubernetes-version v1.13.1 --pod-network-cidr=192.168.0.0/16
mkdir -p $HOME/.kube
sudo cp -i /etc/kubernetes/admin.conf $HOME/.kube/config
sudo chown $(id -u):$(id -g) $HOME/.kube/config
kubectl get pods --all-namespaces
查看節(jié)點(diǎn)信息
kubectl -n kube-system get cm kubeadm-config -oyaml
5.安裝網(wǎng)絡(luò)插件
sudo kubectl apply -f https://docs.projectcalico.org/v3.3/getting-started/kubernetes/installation/hosted/rbac-kdd.yaml
sudo kubectl apply -f https://docs.projectcalico.org/v3.3/getting-started/kubernetes/installation/hosted/kubernetes-datastore/calico-networking/1.7/calico.yaml
查看狀態(tài)
sudo kubectl get pods --all-namespaces
sudo kubeadm version
默認(rèn)情況下钓株,由于安全原因您单,集群并不會(huì)將pods部署在Master節(jié)點(diǎn)上斋荞。但是在開發(fā)環(huán)境下,我們可能就只有一個(gè)Master節(jié)點(diǎn)虐秦,這時(shí)可以使用下面的命令來解除這個(gè)限制:
kubectl taint nodes --all node-role.kubernetes.io/master-
6.node加入到master當(dāng)中
(sudo apt install -y kubelet kubeadm kubectl)
kubeadm join 192.168.1.60:6443 --token gdubb8.7aiem184caduec74 --discovery-token-ca-cert-hash sha256:cdebda5469e0fab9a5695782df577c7c3423193388b8390ad1e3a56276254a8a
token 24小時(shí)有效
重新生成token
kubeadm token create
重新生成--discovery-token-ca-cert-hash
openssl x509 -pubkey -in /etc/kubernetes/pki/ca.crt | openssl rsa -pubin -outform der 2>/dev/null | openssl dgst -sha256 -hex | sed 's/^.* //'
kubeadm join 192.168.1.50:6443 --token bo5g6k.qbb3v6m096uavkrz --discovery-token-ca-cert-hash sha256:f9541fc10907c7374568fff6572a3cbe2042c2149ee2572072db64cb13520a42
給node加上標(biāo)簽平酿,要不然默認(rèn)顯示none
kubectl label node k8s-node1 node-role.kubernetes.io/worker=worker
kubectl label node k8s-node2 node-role.kubernetes.io/worker=worker